diff --git a/.env.example b/.env.example index 4d21c9b..e5aa7fa 100644 --- a/.env.example +++ b/.env.example @@ -13,10 +13,11 @@ EMIT_SECRET= SMTP_USERNAME= SMTP_PASSWORD= -# Email OTP on sign-in. Leave true; only the exact value "false" makes sign-in -# password only (logged as OTP_BYPASSED, shown on the login page and top bar). +# Email OTP on sign-in. Off by default; only the exact value "true" turns it on, +# and that needs working SMTP. While off, sign-in is password only (logged as +# OTP_BYPASSED, shown on the login page and top bar). # Applied to app/config.php by the php container on every start. -OTP_REQUIRED=true +OTP_REQUIRED=false # Port to expose the web app on (default 80) HTTP_PORT=80 diff --git a/app/assets/utils/otp_policy.php b/app/assets/utils/otp_policy.php index 69303b2..b90abc8 100644 --- a/app/assets/utils/otp_policy.php +++ b/app/assets/utils/otp_policy.php @@ -3,21 +3,22 @@ // // Email OTP login policy, set by OTP_REQUIRED in config.php. // -// Fails safe: the OTP step is off only when the constant is defined and is -// exactly the boolean false. A missing constant (any config.php written before -// this switch existed), 0, 'false' or a typo all keep it on. +// OFF BY DEFAULT: the OTP step runs only when the constant is defined and is +// exactly the boolean true. A missing constant (any config.php written before +// this switch existed), 1, 'true' or a typo all leave it off, so sign-in is +// password only and no SMTP is needed to log in. // // While it is off, every sign-in that skips the OTP because of it is logged as // OTP_BYPASSED, and the login page and top bar both say so on screen — a -// weakened sign-in must never be invisible to whoever is using it. +// password-only sign-in must never be invisible to whoever is using it. // -// Only the login OTP is affected. The staff/viewer and no-SMTP skips in -// login_otp.php still apply when it is on, and password-reset OTPs -// (PasswordResetManager) are a separate flow that stays on regardless. +// Only the login OTP is affected. When it is on, the staff/viewer and no-SMTP +// skips in login_otp.php still apply; password-reset OTPs (PasswordResetManager) +// are a separate flow that stays on regardless. if (!function_exists('otp_required')) { function otp_required(): bool { - return !(defined('OTP_REQUIRED') && OTP_REQUIRED === false); + return defined('OTP_REQUIRED') && OTP_REQUIRED === true; } } @@ -26,7 +27,7 @@ if (!function_exists('otp_log_bypass')) { // log (the container's Apache log) under a fixed, greppable tag. function otp_log_bypass($user_id, string $where): void { error_log(sprintf( - '[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED=false in config.php', + '[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED is not true in config.php', (int)$user_id, $_SERVER['REMOTE_ADDR'] ?? '-', $where diff --git a/app/config.example.php b/app/config.example.php index 5d9d720..0366161 100644 --- a/app/config.example.php +++ b/app/config.example.php @@ -39,13 +39,12 @@ if (!defined('NODE_EMIT_SECRET')) { } // ── Login OTP ──────────────────────────────────────────────────────────────── -// Email OTP on sign-in. LEAVE THIS TRUE unless password-only sign-in is wanted -// on purpose (e.g. a demo). It fails safe: anything other than the boolean -// false — the constant being absent included — keeps the OTP step on. While it -// is off, every sign-in is logged as OTP_BYPASSED and the login page and top -// bar both say so. Password-reset OTPs are not affected. +// Email OTP on sign-in. OFF BY DEFAULT: only the boolean true turns it on — +// anything else, the constant being absent included, leaves sign-in password +// only (logged as OTP_BYPASSED, shown on the login page and top bar). Turn it +// on only with working SMTP. Password-reset OTPs are not affected. if (!defined('OTP_REQUIRED')) { - define('OTP_REQUIRED', true); + define('OTP_REQUIRED', false); } // ── Usage packages ─────────────────────────────────────────────────────────── diff --git a/app/include_topbar.php b/app/include_topbar.php index 3f77d7f..9999cd6 100644 --- a/app/include_topbar.php +++ b/app/include_topbar.php @@ -199,12 +199,12 @@ $_usage_full = $_usage_max_pct >= 100; - +
  • + title="OTP_REQUIRED is not true in config.php"> OTP off diff --git a/app/login/index.php b/app/login/index.php index f040332..c79b10b 100644 --- a/app/login/index.php +++ b/app/login/index.php @@ -34,10 +34,10 @@
    - -
    + +
    - Email OTP is temporarily disabled — sign-in is password only. + Email OTP is off — sign-in is password only.
    @@ -59,7 +59,7 @@
    diff --git a/docker-compose.yml b/docker-compose.yml index 85ed542..4b24178 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -22,7 +22,7 @@ services: EMIT_SECRET: ${EMIT_SECRET} SMTP_USERNAME: ${SMTP_USERNAME} SMTP_PASSWORD: ${SMTP_PASSWORD} - OTP_REQUIRED: ${OTP_REQUIRED:-true} + OTP_REQUIRED: ${OTP_REQUIRED:-false} volumes: - .:/var/www/html/wms-app ports: diff --git a/docker/init-env.sh b/docker/init-env.sh index de6b950..f697a72 100755 --- a/docker/init-env.sh +++ b/docker/init-env.sh @@ -55,7 +55,7 @@ PUBLIC_HOST=$public_host EMIT_SECRET=$emit_secret SMTP_USERNAME=$smtp_user SMTP_PASSWORD=$smtp_pass -OTP_REQUIRED=true +OTP_REQUIRED=false HTTP_PORT=$http_port EOF chmod 600 "$ENV_FILE" diff --git a/docker/php/config.php.template b/docker/php/config.php.template index ca80301..20da983 100644 --- a/docker/php/config.php.template +++ b/docker/php/config.php.template @@ -35,7 +35,7 @@ if (!defined('NODE_EMIT_SECRET')) { // ── Login OTP ──────────────────────────────────────────────────────────────── // Set from OTP_REQUIRED in .env and reconciled by the entrypoint on every start. -// Fails safe: anything other than the boolean false keeps the OTP step on. +// Off by default: anything other than the boolean true leaves the OTP step off. if (!defined('OTP_REQUIRED')) { define('OTP_REQUIRED', ${OTP_REQUIRED}); } diff --git a/docker/php/entrypoint.sh b/docker/php/entrypoint.sh index 8aa3e9f..81a09ed 100644 --- a/docker/php/entrypoint.sh +++ b/docker/php/entrypoint.sh @@ -4,10 +4,10 @@ set -e APP_DIR=/var/www/html/wms-app CONFIG=$APP_DIR/app/config.php -# Email OTP on sign-in. Anything but the exact string "false" means required, -# so a typo or a missing variable can never switch it off. -: "${OTP_REQUIRED:=true}" -[ "$OTP_REQUIRED" = "false" ] || OTP_REQUIRED=true +# Email OTP on sign-in, OFF BY DEFAULT. Only the exact string "true" turns it +# on; a missing variable or anything else means false. +: "${OTP_REQUIRED:=false}" +[ "$OTP_REQUIRED" = "true" ] || OTP_REQUIRED=false export OTP_REQUIRED # Generate app/config.php from template on first run only. @@ -34,7 +34,7 @@ else echo "[entrypoint] added OTP_REQUIRED = ${OTP_REQUIRED} to an existing config.php" fi if [ "$OTP_REQUIRED" = "false" ]; then - echo "[entrypoint] WARNING -- email OTP is OFF; sign-in is password only." + echo "[entrypoint] email OTP is off (OTP_REQUIRED=false); sign-in is password only." fi mkdir -p "$APP_DIR/app/uploads"